Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Jun 2020de heer YThe APD Litigation Chamber fined de heer Y 5,000 EUR. It found that personal data from the municipal staff list was processed for election propaganda, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
19 Oct 2020PREDASE SERVICIOS INTEGRALES SOCIEDAD LIMITADAPREDASE SERVICIOS INTEGRALES S.L. was fined EUR 5,000 by the AEPD for failing to publish a privacy policy on its website and for misleadingly using the AEPD logo. The conduct could imply an association with the authority and influence user decisions.ESAEPDGDPR€5,000
01 Jan 2024EDA TV CONSULTING S.L.EDA TV CONSULTING S.L. was fined 5,000 EUR by the AEPD for publishing a minor’s image without consent. The case concerns a breach of data protection rules and the child’s privacy rights.ESAEPDGDPR€5,000
16 Jun 2025Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards.CYΕπίτροπος Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
12 Dec 2023COMMUNECNIL imposed a EUR 5,000 fine on COMMUNE and issued an injunction. The case concerns a regulatory breach requiring corrective action.FRCNILGDPR€5,000
22 Feb 2024Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means.ITGaranteGDPR€5,000
17 Apr 2017WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial communications by email. The conduct violated the recipient's request to opt out of advertising.ESAEPDePrivacy€5,000
14 Sept 2023AUTOCINES 2015, S.L.AUTOCINES 2015, S.L. was fined by the AEPD 5,000 EUR for posting a child’s photo on social media without parental consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€5,000
01 Oct 2023wspólnota mieszkaniowaUODO found that the housing community breached GDPR requirements. The case concerned improper processing of personal data and required supervisory intervention.PLUODOGDPR€1,080
14 Sept 2023Nimbus s.r.l.Nimbus s.r.l. was fined by the Garante 5,000 EUR for using a fingerprint-based attendance system. The authority found that employees were not properly informed and that the required consent was not obtained.ITGaranteGDPR€5,000
21 Oct 2022CASAL DE L'ESPLUGA DE FRANCOLÍCASAL DE L'ESPLUGA DE FRANCOLÍ was fined by the AEPD for publishing a video on social media without consent. The recording showed a minor during a sports event, which constituted a breach of data protection rules.ESAEPDGDPR€5,000
01 Jan 2015CABLEUROPA SAUCABLEUROPA SAU was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails and SMS messages to a customer. The recipient had previously exercised the right to cancel and opted out of receiving such communications.ESAEPDePrivacy€5,000
01 Jan 2014HOSPITAL VETERINARIO LA MORALEJA, S.L.HOSPITAL VETERINARIO LA MORALEJA, S.L. was fined by the AEPD 5,000 EUR for sending unsolicited commercial communications by electronic means. The authority found that recipients were not given an option to object to receiving such messages.ESAEPDePrivacy€5,000
29 Apr 2021FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards.ITGaranteGDPR€5,000
03 Jun 2020Dane anonimowe (Panią A. T. prowadzącą działalność gospodarczą pod nazwą)UODO imposed a PLN 5,000 administrative fine on Dane anonimowe (Panią A. T. prowadzącą działalność gospodarczą pod nazwą). The case concerned a failure to provide information requested by the supervisory authority.PLUODOGDPR€1,133
13 Nov 2025SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL CHAUSSURES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL CHAUSSURES under a simplified procedure. The decision is dated 13 November 2025.FRCNILGDPR€5,000
20 Oct 2025S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information.ROANSPDCPGDPR€5,000
27 Dec 2023ASSOCIATION PROMOUVANT DES ACTIONS AU SEIN D'UNE COMMUNE (procédure simplifiée)CNIL imposed a 5,000 EUR fine on ASSOCIATION PROMOUVANT DES ACTIONS AU SEIN D'UNE COMMUNE and issued an injunction. The case concerned a confirmed data protection breach handled under a simplified procedure.FRCNILGDPR€5,000
27 Nov 2025Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24.BEAPDGDPR€5,000
01 Jan 2021ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules.ESAEPDGDPR€5,000